I break the trust boundaries inside autonomous AI systems and libraries — then help vendors close them. Coordinated disclosures to Microsoft, Amazon, Apple, Cloudflare, Discourse and CERT-In, one assigned CVE, and a credited fix in Amazon's Kiro agent platform.
::--:
=+oxX##@@@@@##Xxo+=
:- :=oX#@%@@@@@@@@@@@@@@@%@#Xo+: :-
:x@@#Xx*+-: :+x#@@@@@@@@@@@@@@@@@@@@@@@@@@@@x+- -=+oxX@@@#
=#@@@&&&%@@#xx#@@@@@@@@@@###@@@@@@@@##@@@@@@@@@@#X##@%%&&%@@@%+
o@@@@@%%&%##@@@@@@@@@@@@#*+*X%@@@@#*++#@@@@@@@@@@@@%%%%%@@@@@@x
X@@@@@@%@xX@####@@@@@@@@@o+**ooooo****#@@@@@@@@@@@@@@%%%#@@@@@#
:X@@###%#oX#x*o#@@@@@@@@@x+*%X+++++x%o+x@@@@@@@@@@@@@@@@%%@#@@@#
X#o**xXx#@#o*oxx#@@@@@@@o+*o*oxxxo*o*+*@@@XX#@@@@@@@@@@@@o*ox##
o***xXX@%X*oXX**X@@@@@@@#x+++**+**+++oX@@*=++@@@@@@@@@@@@#o**oo
+o*xX#@#=+*--@x=x#@@@@@@@@#xxooxooxxX@@@@X*ox@@@@@@@@@@@@@Xo*o=
-xoX@@@X ox-=XXX##@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Xox:
+#@@@@#*--Xxx#@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@#=
X@@@@@#Xx#x+o@@@@@@##XXXxxxoooooxxxXXX##@@@@@@@@@@@@@@@@@@X
:@@@@@@xxxX##@@@#Xxoo*******************ooxX##@@@@@@@@@@@@@@-
*%@@@@@###@@@Xxo*******oooxxxxXXxxxooo*******oxX#@@@@@@@@@@%*
:%%%%%%@@@%#xo****oooxXX#@@%%%%%%%%%%@##Xxxoo****ox#@@@@@%%%%%-
x&%&&&&%%XoooooxX#@@%%&&&&&&&&&&&&&&&&&%%%@#Xxxoooox%%&&&&%&@
:*&&&&&&&%xoxX#@%%&&&&&&&&&&&&&&&&&&&&&&&&&&&%%@@#Xxo%&&&&&&@=
=*oxXx#@@%%%#@%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@@%%@@@@%X :++
:- :=o#X####X@%%@@@%%%%%%%%%@@@%%%%%@#@@#@@%%%%%%%%%%%%%%@###########o:
=oxXXX@@###@#######@@@@%%%%@####@@@@##X@X##@%##@#@#######@#######%@o=:
-= -:+@###@#############@@@@@@@#############%X*X#@############@##@%X=
*-:*@@@@@###@####@##################@####Xo%o-=X@@#######@###%%@@@%%#+:
:=x@%@@@@###@@####@@####@Xo####@####@####@x*@+-:-XXX@@@###@@@@%%%%@%XX##x+=
*X%%%@@@%%%%%####@%@###o=o###Xox@######@x=-+::::-x=X@@###@%@@%%%%#XX*+---:
-=--X#@%%%%@###%%%%%@Xx##@#*-X#xX###@X+=*oxX###@@#%%###@@@%%%@%*
:###%%%%@###%&&&&&%%%&&&%%%#X##@@%@%&&&&&&&&&&&&%###@@@%%%@@=
X@%@@%#x@@##@&%&&%&&&&%&%%@@@@@#@&&&%%%%%%%%%%%&%##@@##%%%@@X=
:x%@%%%@-=#@@@#%&&%&&%&&&&%%%%%@#X@&%&&&&&&&&&%%&%##@@@*=@%%@o#@#x**=:
=++ox###@%%%@-=X@@@%@%%&&&&&&&%%%&%xxxxx%&%%%&&&&&&&&%@%@@@X+:@%%%X++**=-
=xX#@@Xx%%o:=#@@@%%@@%%%%%%&&&%*:::::=@&&&%%%%%%@@@%%@@@*:*%@X#%%#o+:
:-: =%@%X=*@@@@x##%&&&&&%@x=::----:-o#%&&&&&%@#X@%@@x=x%@%+ :--:
-@@%%%#@@##x-=+****+=-::-:::::-:::=+****+=-o##@@@@%%@%*
=@@%%%%%%%o*+-::::::::--::::::::-:::::::-:=**@@%%%%%@%*
-+*xo@%@*x%%%%+:--------::::::::::::::---------#%%%x+#%@oxo+-
+%o x%%%%%o-::---::::::-----:-::::---:::+@%%%%X *%x
Xo *Xx#@x@%#*-::::----------------:::-*#%#*##ox*: *X
=- o**@%&&%Xo=:::::-------:::::=*X%&&%@*** --
x@%&%&%%&&&%@x*=-::::::::=+x#%&&&%%&&&%%X:
X%%%&&&%%%&&&&%@Xx*++oX@%&&&&%%%&&&%%%X
+%X%%&&&&&&%%%%&&&&&&&&&&%%%%&&&&&%%#%+
+: +@%&&&&&&&&@x#@%&%@#X#&&&&&&&&%@* -+
-*o@@%&&&&&@XxoooxXxoooxX#&&&&&%@@o+-
-+o#%%%%%@%&&&xooxoooooooxxox&%&%%%%%%%#o+-
*oxXX#@%%%&%@%%%@xooxxxxxxxoox@@@%@%&%%@@@@#Xo*
*XX#@@@@@@@%&&%%%%@o+++***+==o@@@%%&&%%%%@%Xo##X*
=XX@%@@@@@@@@@%%%@@@@Xo=----+X%@%%@%%%%%#@xo##@%XX+
=Xx@%@@@@@@@@@@@@@#%@@%%@x**#%%@@%@@%%@X#ox@@%%%%%xX=
Every item below was validated with a purpose-built reproduction — a real test harness or direct-call proof of concept, never a generic scanner. Several remain under coordinated-disclosure hold.
Class, impact, status and references — at advisory altitude. Tap any row to expand. No exploit payloads are published here.
The highest-impact work — an agent-platform RCE chain, a runtime CVE, and an unauthenticated RCE review.
An independent source review plus executed PoCs surfaced 7 findings in Amazon's Kiro agent platform. Chained, a scheduled-job hijack removed the human-approval step and ran at full owner privilege — the strongest map-to-real of indirect prompt injection and agent-sandbox escape. All seven fixed; reporter credited in the repo contributor list.
Apple's Swift Linux-container runtime resolved build-context symlinks against the host during filesystem sync, so a malicious builder peer could read files outside the build context by name. CWE-22, CVSS 4.3. Fixed in container 1.2.0; a sibling advisory covers the same resolver's JSON walk mode.
A security review of Cloudflare's computer-use project produced six findings — three proven with PoCs: an unauthenticated WebSocket remote-code-execution path, a CSRF-drivable POST, and an SSRF. Submitted through HackerOne and under vendor assessment.
An 80B model at ~23 tok/s on a 6 GB laptop — by measuring the machine instead of trusting defaults. Profiles hardware, predicts a model's speed before download, then tunes by measurement: CUDA-backend detection, CPU-governor fixes, RAM budgeting, thread pinning, and MoE expert placement.
Advanced AI security & code-review skill for auditing LLM, agentic, MCP and full-stack apps — OWASP LLM/Agentic Top 10, AIVSS, MITRE ATLAS, NIST AI RMF, scanner integration and HTML/PDF reporting.
Privacy-hardened PII framework using ViT + LLMs + locality-sensitive hashing — 98.6% data utility at sub-0.1% re-identification across 6 attack types.
A multi-agent security-operations platform: LLM log triage with a hash-chain audit trail and anomaly detection.
CA-free post-quantum web authentication using ML-DSA/ML-KEM, FROST threshold signatures and a BLAKE3 Merkle transparency log.
An LLM claim-verification library — published and installable, built to check model outputs against grounded evidence.
Latent Coherence Elicitation — a framework for probing latent-space coherence in language models.
Payment-governance layer for autonomous agents — ML anomaly detection, SHA-256 hash-chain audit and a pub/sub kill switch.
An open-source Python project — repository linked; a short summary can be added on request.
Special mention · 2nd consecutive year
Case 103869 · Feature Bypass, fixed
Credited · PR #6923 · debasishtripathy13
Met the PyRIT team, Rehberger & E. Lim
ISRO · IISc · DRDO — up to CVSS 9.9
PHANTOM 2025 · SL Metrics · Vastu CV (IJAC)
1st · 2024
Winner · 2024
Winner · 2024
2nd · 2025
3rd · SentinelPay · 2026
1st · 2024
AI red-teaming, agent-security, LLM-library hardening, or a coordinated disclosure — I respond promptly.